Controlled Unclassified Information: 

Recommendations for Information Control Reform 



• OMB Waich 



July 2009 



2 



Recommendations for Information Control Reform 



Acknowledgements 

This OMB Watch report was written by Sean Moulton, Roger Strother, and Chris George. We thank 
the following individuals for their feedback on the report during drafting: Meredith Fuchs, National 
Security Archive; Steven Aftergood, Federation of American Scientists; Sharon Bradford Franklin, 
Constitution Project; Michael German, American Civil Liberties Union; Patrice McDermott, 
OpenTheGovernment.Org; and Danielle Brian, Project on Government Oversight. While these 
individuals provided input and edits on our recommendations, their assistance does not necessarily 
constitute support of the final product. 



Executive Summary 



While many people probably have a general grasp of the meaning and importance of classified 
information, most probably don't know the meaning of Controlled Unclassified Information (CUI], 
Sensitive But Unclassified information (SBU], or the host of other non-classified labels. 
Unfortunately, too many of the people who are confused about these information categories work 
for the very agencies using the labels. 

The CUI and SBU (an earlier catch-all term that often referred to any and all labels that were not 
part of the official classification system] are typically categories of records that need special 
handling to protect the information from inadvertent disclosure. For example, the records may 
contain privacy information or details about an ongoing investigation. 

The labels were meant to make government employees' jobs easier. Flowever, as the number of 
different labels grew over the years, fewer and fewer people understood exactly what restrictions 
applied to each label. 

The lack of confidence and certainty about how information stamped with such labels should be 
handled results in officials shutting down almost all access to the data by anyone else. Thus, in 
attempting to prevent possible misuse of the information, the government has often prevented any 
timely legitimate use of the records, as well. Other federal agencies, state officials, local law 
enforcement, and the public get locked out and never fully benefit from information the 
government has spent taxpayer dollars collecting. 

Failures of government agencies to connect the dots between different pieces of information held 
by different agencies highlighted the fact that "over-protection” of records could easily lead to 
under-use of the information. 

In May 2008, President George W. Bush issued a memo that replaced the numerous SBU labels with 
a uniform designation entitled "controlled unclassified information" that contained three tiers of 
safeguarding procedures and dissemination controls. The goal was to standardize practices and 
thereby improve the sharing of information among government officials. However, there are 
several other well known SBU problems that were left unaddressed by Bush’s memo, such as the 
need to reduce the amount of information with such control markings and the need to improve 
public disclosure of information that does not need to be withheld. If the problems remain 
unaddressed, we will miss a major opportunity to overhaul a problematic system. 





3 



Recommendations for Information Control Reform 



Just a few months after taking office, President Barack Obama issued a memo on classification and 
SBU that reopened the door on the process of overhauling these unclassified information 
categories. Obama created an Interagency Task Force to review SBU practices, create metrics for 
measuring agency progress implementing the CUI framework, and within 90 days, report back with 
recommendations on how to proceed. 

This report attempts to outline the problems associated with SBU information categories and the 
current process to reform them into a simpler, more manageable system. We offer clear 
recommendations to the Task Force and the Obama administration on how to address these issues. 

The most expedient method to address the CUI problems would be a memo from Obama that would 
amend the original instructions and clarify any issues that went unaddressed in the Bush memo. 
We urge the interagency task force to recommend the creation of a new CUI policy with these 
problems in mind. 

If properly implemented, the CUI framework should improve management of information, reduce 
the number of different control labels used, and reduce the amount of information being 
categorized so the system can operate more effectively. The new memorandum should also seek to 
maximize disclosure to the public by prohibiting reliance on control labels in making FOIA 
determinations, requiring portion marking of records to allow greater use of partial disclosures, 
and establishing time limits on labels that would allow the records to be more widely shared after 
the period of sensitivity has passed. Oversight of the program, such as audits and regular reports 
by agencies, should be embraced to ensure the reform efforts don't mistakenly cause even greater 
overuse of control labels. 

The CUI framework should also include requirements for training and enforcement to drive timely 
implementation. Additionally, clear policies are needed to protect whistleblowers who disclose CUI 
records to uncover waste, fraud, and mismanagement. 

Sean Moulton, 

Director, Federal Information Policy 
OMB Watch 



The Origins of Sensitive But Unclassified Information 



The Cold War led to a considerable restructuring of the United States government. The modern 
national security and intelligence apparatus was created to address the challenges and threats of a 
bipolar world in which the United States and the Soviet Union were dominant superpowers. A 
variety of disparate intelligence services were created with specific missions. Each fiercely 
protected its individual turf, and there was little occasion or impetus for information sharing 
between agencies. Furthermore, there was little reason for cooperation between agencies with a 
foreign or domestic focus when national security threats were perceived as external. 

In this environment, there were a variety of policies implemented to protect information, both at 
the level of the individual agencies and across the federal government. Classification was created 
and expanded by Executive Order to protect nuclear secrets and other information pertinent to 
national security. In the 1970s, agencies began to identify sensitive but unclassified information 
(SBU] that did not meet the criteria for classification but nonetheless was thought to need more 
secure handling to prevent inadvertent disclosure. A multitude of SBU designations proliferated, 
eventually reaching more than 100 markings across the federal government, including such labels 





Recommendations for Information Control Reform 



as For Official Use Only (FOUO], Security Sensitive Information (SSI], 1 and Law Enforcement 
Sensitive (LES], 

Four principal SBU problems complicated information sharing across the government. First, SBU 
categories were vaguely defined and unevenly implemented across government agencies. Second, 
authority to mark documents as sensitive was so decentralized within agencies that often virtually 
anyone employed by the agencies could label information, including government contractors. 
Third, government agencies have sometimes incorrectly interpreted SBU as being automatically 
exempt from requests under the Freedom of Information Act [FOIA] and other information 
disclosure and sharing processes. Fourth, the SBU categories had no time limits on how long 
information was to remain controlled and no review procedures to improve implementation over 
time. 2 These problems resulted in a confusing system that excessively applied the SBU category 
and permanently restricted all information. 

SBU has become a more significant concern in recent years. A March 2002 memorandum by White 
House Chief of Staff Andrew Card instructed departments and agencies to control not only classified 
information, but "other information that could be misused to harm the security of our nation and 
the safety of our people.” 3 This was consistent with the Bush administration's tendency to 
maximize information withholding and led to an increased use of SBU labels. 

The Homeland Security Act of 2002 authorized the Department of Homeland Security [DHS] to 
label and protect sensitive information - though it remained undefined - and share it with local and 
state government entities and relevant individuals in the private sector, provided that they sign 
nondisclosure agreements. This legislation provided an extraordinary amount of discretion to DHS 
and further contributed to a culture of "when in doubt, withhold." DHS issued a May 2004 directive 
requiring employees to mark as "For Official Use Only" any "sensitive but unclassified information" 
generated or received by DHS. 4 

Thus, the multitude of SBU categories, agency subjective definitions, and unclear disclosure policies 
created a breeding ground for unchecked government secrecy. Over several years and numerous 
investigations, the Government Accountability Office found that agencies lacked clear policies, 
oversight, and training on handling sensitive information. This lack of uniform meanings for 
information labels and dissemination standards across agencies created great uncertainty in if and 
how information could be shared and with whom, which resulted in increased withholding. 



1 SSI is one category of SBU that was not created at the discretion of an agency, but by statute. It has its origins with the 
Air Transportation Security Act of 1974, which permitted the FAA to not disclose information that would violate privacy, 
reveal trade secrets, or reduce safety. 

Unformation classified in accordance with Executive Order 12958, as amended, is much more vigorously regulated. Only 
a select group with proper training and security clearances are permitted to classify documents that fall within a strict 
definition of eligibility. There is additionally an automatic declassification date depending on the level of classification, set 
at no more than 10 years from the original classification. Only after review can this original period be extended, and only 
for information fitting established criteria. 

3 Andrew H. Card, Jr., "Action to Safeguard Information Regarding Weapons of Mass Destruction and Other Sensitive 
Documents Related to Homeland Security,” Memorandum for Heads of Executive Departments and Agencies, 
<http://www.usdoj.gov/oip/foiapost/2002foiapostl0.htm> 

4 "SBU - Sensitive But Unclassified Information, and FOUO - For Official Use Only,” Coalition of Journalists for Open 
Government, <http://www.cjog.net/background_sbu_sensitive_but_unclass.html> 



5 



Recommendations for Information Control Reform 



Critiques of Information Sharing 



In October 2007, the National Strategy for Information Sharing identified several core principles: 

• Effective information sharing comes through strong partnerships among 
Federal, State, local, and tribal authorities, private sector organizations, and our 
foreign partners and allies; 

• Information acquired for one purpose, or under one set of authorities, might 
provide unique insights when combined. ..with seemingly unrelated information 
from other sources, and therefore we must foster a culture of awareness in 
which people at all levels of government remain cognizant of the functions and 
needs of others and use knowledge and information from all sources to support 
counterterrorism efforts... 5 

However, the goal of increased and improved information sharing in the United States government 
is hardly new. A need for reform along the lines of similar ideals has been echoed for the last three 
decades. In 1975, as activities of the intelligence community during the Vietnam War and the Nixon 
administration were being investigated, the White House prepared a briefing book on potential 
reforms and recommended actions for President Gerald Ford. In the first paragraph, it is noted, 
"Critics outside the Administration and Community leaders have recognized the need to improve 
protection of secrecy and, at the same time, to provide for wider dissemination of intelligence 
product to those who have a need to know." 6 This is the essential conundrum of information 
sharing: how to provide for greater exchange of information while still securing sensitive 
information from those who would use it for detrimental purposes. 

Despite this early identification of a problem, information sharing did not receive serious attention 
until after the terrorist attacks of Sept. 11, 2001. The National Commission on Terrorist Attacks 
Upon the United States - "the 9/11 Commission" - identified a critical failing in the months before 
the attacks: "Information was not shared, sometimes inadvertently or because of legal 
misunderstandings. Analysis was not pooled.... Often the handoffs of information were lost across 
the divide separating the foreign and domestic agencies of the government." 7 Structural barriers, a 
lack of common standards, and excessive complexity and secrecy were cited as impediments to a 
unified effort in intelligence gathering and analysis. They proposed not only a reorganization of the 
intelligence community, but the creation of an information network linking government agencies 
and a seismic shift in the culture of information. 

Cold War security practices were found to "nurture overclassification and excessive 
compartmentation of information among agencies.... Agencies uphold a 'need-to-know' culture of 
information protection rather than promoting a 'need-to-share' culture of integration." 8 A standard 
of information sharing is needed not only between agencies of the federal government, but across 
levels of government. Prevention of and response to future emergencies requires coordination 
among federal agencies with both foreign and domestic focus and law enforcement officials, health 
care workers, and other emergency response services in the communities themselves. This level of 



5 National Strategy for Information Sharing: Successes and Challenges In Improving Terrorism-Related Information 
Sharing, October 2007, 2-3. 

6 Dick Cheney, Intelligence Community Decision Book for the President, <http://www.fas.org/irp/eprint/ford-intel.pdf> 

7 Final Report of the National Commission on Terrorist Attacks Upon the United States, <www.9-llcommission.gov>, 353 

8 Final Report of the National Commission on Terrorist Attacks Upon the United States, 417. 





6 



Recommendations for Information Control Reform 



coordination was not possible when each agency independently set standards for controlling 
information it possessed. 

SBU was part of the information sharing problem. Organizational cultures favored greater control 
over information rather than greater disclosure. Through decentralized control of marking 
procedures, the number of designations and their use proliferated. Without consistent handling 
practices between agencies, confusion reigned over who would have the authority to view what 
information. And in the end, necessary information was not being sent to the relevant agencies. 



Implementation of Controlled Unclassified Information 



To improve the sharing of homeland security information, the Intelligence Reform and Terrorism 
Prevention Act of 2004 required the president to establish an Information Sharing Environment 
with uniform policies and standards across levels of government, including key components of the 
private sector. Bush issued a December 2005 memorandum directing that SBU be standardized 
across the government and established an interagency Sensitive But Unclassified Coordinating 
Committee. Bush eventually issued a May 2008 memo, replacing the multiple SBU categories with a 
uniform designation entitled "controlled unclassified information." 

The memo defined controlled unclassified information (CUI] as: 

unclassified information that does not meet the standards for National Security 
Classification under Executive Order 12958, as amended, but is (i] pertinent to the 
national interests of the United States or to the important interests of entities 
outside the Federal Government, and (ii] under law or policy requires protection 
from unauthorized disclosure, special handling safeguards, or prescribed limits on 
exchange or dissemination. 9 

Within the CUI designation, the memo established a three-tiered system of safeguarding procedures 
and dissemination controls: Controlled with Standard Dissemination, Controlled with Specified 
Dissemination, and Controlled Enhanced with Specified Dissemination. Agencies were prohibited 
from creating any additional labels. This memo ostensibly intended "to standardize practices and 
thereby improve the sharing of information, not to classify or declassify new or additional 
information." However, as the Information Sharing Environment is specific to terrorism-related 
information, a vast quantity of SBU information was left unaddressed. 

The Bush memo assigned responsibility for the implementation of CUI to the National Archives and 
Records Administration (NARA]. As "Executive Agent," NARA is responsible for developing 
standards and implementation guidance, monitoring compliance, establishing training, and creating 
enforcement mechanisms and penalties. A new CUI office was created under the Information 
Security Oversight Office, which was created in 1978 to oversee the classification system. While 
NARA is principally concerned with the preservation of historical documents rather than 
management of current records, the agency's dedication to information preservation and 
objectivity was seen as critical to the new program's objectives. 

On May 27, 2009, Obama issued his own memorandum calling for a review of classification policy 
and controlled unclassified information. This new memo states "the process of implementing the 



9 President George W. Bush, "Designation and Sharing of Controlled Unclassified Information (CUI},” Memorandum for the 
Heads of Executive Departments and Agencies, May 9, 2008. 





